RRL and avoiding contributing to DDoS (Was: How to suppress ADDITIONAL SECTION per zone)

2013-07-05 Thread Dave Warren
On 2013-07-05 07:21, John Wobus wrote: I endorse this suggestion: we were faced with such attacks and were naturally leery about issues we might run into running a patched bind and the additional tuning it could require. Our experience is: the RRL patch, used with its default parameters, simply

Re: RRL and avoiding contributing to DDoS (Was: How to suppress ADDITIONAL SECTION per zone)

2013-07-05 Thread Vernon Schryver
From: Dave Warren da...@hireahit.com I haven't been following the RRL discussions too closely, is this patch scheduled to be included in BIND9 proper or will it remain a patch? } From: Evan Hunt each at isc.org } It's not built into bind (yet). } } Correct. For the record, it'll be in